# Laravel security policy bypass in 12.x, 13.x

Published: 2026-06-08 · Severity: medium
Canonical: https://vorant.io/reports/3fa1da0e-3aae-446f-948d-fef3a51b1493/laravel-security-policy-bypass-in-12-x-13-x

> A vulnerability in Laravel framework versions before 12.61.1 and 13.12.0 allows attackers to bypass security policies.

The French CERT (CERT-FR) has issued an advisory for a security policy bypass vulnerability affecting the Laravel PHP framework. The flaw impacts Laravel versions 13.x prior to 13.12.0 and all versions in the 12.x branch prior to 12.61.1.

The vulnerability, tracked as CVE-2026-48041 and documented in GitHub Security Advisory GHSA-crmm-hgp2-wgrp, enables attackers to circumvent established security policies within Laravel applications. The advisory was published on June 8, 2026.

Organizations running affected Laravel versions should consult the vendor's security bulletin and update to patched versions 12.61.1 or 13.12.0 as appropriate for their deployment.

## Mentioned in this report

- Vulnerabilities: CVE-2026-48041

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0703

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3fa1da0e-3aae-446f-948d-fef3a51b1493/laravel-security-policy-bypass-in-12-x-13-x.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
